Legal

Privacy Policy

Effective date: September 5, 2026  ·  Operator: Toros Workshop LLC d/b/a Toros Laboratories  ·  Privacy contact: privacy@chiru.io

What we do

  • Store your email, display name, and profile settings
  • Encrypt every platform token with AES-256-GCM before storage
  • Read analytics for your own posts from each platform's API
  • Process payments via Stripe, Paddle, the App Store, and Google Play
  • Hold media you schedule only until it publishes, then delete it

What we don't do

  • Sell, rent, or license your personal information
  • Use your content to train AI models
  • Track you across other apps or sites for advertising
  • Show ads, or include ad SDKs in our apps
  • Keep your video after the feature you used it for is done

This summary is for convenience and does not replace the full policy below.

Contents

  1. Introduction and scope
  2. Definitions
  3. Information we collect
    1. Information you provide to us
    2. Information from connected platform accounts
    3. Information about other people in your account
    4. Media and creative content
    5. Information collected automatically
  4. AI features and your own API keys
  5. Public profiles and share cards
  6. How we use your information, and our legal bases
  7. Trending hashtags and aggregated data
  8. How we share your information
  9. International data transfers
  10. How long we keep your information
  11. How we protect your information
  12. Your rights and choices
  13. Regional privacy notices
  14. Children's privacy
  15. Communications, marketing, and push notifications
  16. Team and Agency workspaces
  17. Changes to this policy
  18. How to contact us

1. Introduction and scope

Toros Workshop LLC, a North Carolina limited liability company doing business as Toros Laboratories, provides this Privacy Policy to explain how we collect, use, store, share, and protect personal information when you use the Chiru application, the websites at chiru.io and its subdomains, our mobile applications for iOS and Android, our browser-based editors, our application programming interfaces, and any related services we provide (collectively, the "Service"). This policy also describes the rights and choices available to you and how to contact us to exercise them.

This policy applies to the personal information of people who create Chiru accounts, connect social-media accounts to Chiru, visit our websites, contact our support team, or otherwise interact with the Service. Where the Service is used by a business, agency, or team, we also process personal information on behalf of that customer as described in Section 16.

Use of the Service is also governed by our Terms of Service, which are incorporated into this policy by reference. Capitalized terms not defined here have the meanings given in the Terms of Service.

We are the data controller for the personal information described in this policy, except where Section 16 describes circumstances in which we act as a processor on behalf of a customer.

2. Definitions

"Personal information" means any information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with an identified or identifiable individual.

"Connected platform" means a third-party social-media or content service you authorize Chiru to access on your behalf, currently including YouTube, TikTok, Instagram, Facebook, Threads, X (formerly Twitter), LinkedIn, Pinterest, and Bluesky.

"Platform data" means information we receive from a connected platform through its official API, including your profile information, access tokens, the posts you publish through Chiru, and the statistics and engagement data associated with those posts.

"Petal" means a single connected platform account within your Chiru account.

"Sub-processor" means a third-party service provider that processes personal information on our behalf to help us operate the Service.

3. Information we collect

3.1 Information you provide to us

Account and profile information. When you create an account, we collect your email address and a display name. You may optionally provide a public username, a short bio, a content niche or category, a country or region for regional trending features, and brand-kit assets such as a logo, colors, and fonts. The profile image shown for a connected account in Chiru is the avatar from that platform account; Chiru does not store a separate profile photo that you upload. Passwords are handled by our authentication provider, Supabase, which stores them only in hashed form (bcrypt); Chiru never has access to your password.

Payment information. When you purchase a subscription, payment is handled by a third-party payment processor. On the web, subscriptions in the United States are processed by Stripe, and subscriptions outside the United States are processed by Paddle, which acts as the merchant of record for those sales. In our mobile applications, subscriptions are processed by the Apple App Store or Google Play, with subscription state managed through RevenueCat. We do not receive or store your full payment card number. We receive and retain transaction identifiers, the plan you purchased, billing dates, and the billing country or region so that we can provide the Service and keep required financial records.

Content you create. We collect the captions, hashtags, titles, descriptions, scheduling preferences, per-platform publishing settings, campaign names, and other text you enter when composing or scheduling posts, as well as editing settings, templates, and project metadata associated with the creative editors described in Section 3.4.

Support communications. When you contact us for help, we collect the contents of your message, your contact details, and any attachments you choose to send. Support conversations may be handled through an in-app support assistant, email, or both.

Consent and agreement records. We keep a record of your cookie and privacy choices, and of the date and time you accepted our Terms of Service and this policy, so that we can demonstrate compliance with applicable law.

Team information. If you are added to another user's Agency workspace, or you add team members to your own, we collect the email addresses and roles of workspace members and records of the actions they take within the workspace. See Section 16.

3.2 Information collected from connected platform accounts

Chiru's core function is to publish content to, and read analytics from, the social-media accounts you choose to connect. When you connect a platform, Chiru requests authorization through that platform's official OAuth or equivalent authorization flow, and you are shown the specific permissions being requested before you approve them. We request only the permissions needed for the features you use.

For every connected platform, we may collect: your platform username, handle, or channel name; your profile image; your platform account identifier; the access and refresh tokens that let Chiru act on your behalf; the content of the posts you publish through Chiru; and engagement and performance statistics for those posts, such as views, likes, comments, shares, saves, reach, impressions, and follower counts, to the extent the platform makes them available.

All platform access tokens are encrypted with AES-256-GCM before they are written to storage, and are decrypted only in memory at the moment they are needed to make an API request on your behalf.

The following platform-specific disclosures are required by the respective platforms or describe material differences in what we access.

Google and YouTube. Chiru uses YouTube API Services. When you connect YouTube, you are accessing YouTube content and features that are subject to the YouTube Terms of Service. Chiru uses these services to upload videos you choose to publish, to read statistics for your own videos and channel, to read and respond to comments on your own videos, and to display YouTube performance analytics including watch time and audience retention. Chiru's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google's own handling of your data is described in the Google Privacy Policy. You can revoke Chiru's access at any time by disconnecting YouTube inside Chiru or through your Google security settings.

TikTok. Chiru uses TikTok API Services. When you connect TikTok, Chiru requests only the permissions needed to do what you ask it to do: user.info.basic (your display name, avatar, and account identifiers, so Chiru can show you which account a post is going to) and video.publish (so Chiru can publish the videos you choose to publish using TikTok's Direct Post flow). Two further permissions are requested only if you use the features that need them and only once TikTok has approved them for our application: user.info.stats (account totals such as follower, like, and video counts) and video.list (views, likes, comments, and shares on your own posts). Both exist solely to populate your analytics dashboard. Chiru never posts anything you have not explicitly sent, does not read other users' videos, profiles, comments, or private messages, and does not use TikTok data for advertising, resale, or to train artificial-intelligence models. Chiru's use of information received from TikTok adheres to the TikTok Developer Terms of Service. TikTok's own handling of your data is described in the TikTok Privacy Policy. You can revoke Chiru's access at any time by disconnecting TikTok inside Chiru, or from TikTok directly under Profile → Settings and privacy → Security and permissions → Manage app permissions.

Meta: Instagram, Facebook, and Threads. When you connect an Instagram professional account, a Facebook Page, or a Threads account, Chiru accesses your profile information, the content you publish through Chiru, the comments on that content, and insights about your posts and account, through Meta's official APIs and only within the permissions Meta has approved for our application. Chiru uses this information solely to provide the Service to you. Chiru does not use Meta platform data to build or augment user profiles, for advertising, or for any purpose other than providing the features you use. You can revoke Chiru's access at any time by disconnecting the account inside Chiru, or from Facebook under Settings → Apps and Websites, or from Instagram under Settings → Apps and Websites. Meta's own handling of your data is described in the Meta Privacy Policy. See Section 12 for Meta-specific data-deletion instructions.

X (formerly Twitter). When you connect an X account, Chiru accesses your profile information and publishes the posts you choose to publish. Because X charges for publishing through its API, X posting is metered separately at the rate shown on our pricing page, subject to a spending limit that you control. We keep records of your X posting activity and spending-limit changes as described in Section 10. X's own handling of your data is described in the X Privacy Policy.

LinkedIn. When you connect a LinkedIn profile or page, Chiru accesses your profile information, publishes the posts you choose to publish, and reads engagement statistics for those posts, within the permissions LinkedIn has approved for our application. LinkedIn's own handling of your data is described in the LinkedIn Privacy Policy.

Pinterest. When you connect a Pinterest account, Chiru accesses your profile information and boards, publishes the pins you choose to publish, and reads engagement statistics for those pins. Pinterest's own handling of your data is described in the Pinterest Privacy Policy.

Bluesky. When you connect a Bluesky account, Chiru establishes a session with your personal data server using the AT Protocol, publishes the posts you choose to publish, and reads engagement statistics for those posts. Bluesky session credentials are encrypted with AES-256-GCM and stored in the same manner as other platform tokens.

For every platform, you can revoke Chiru's access at any time by disconnecting the account inside Chiru or through the platform's own settings. Revoking access from either place stops all future publishing and analytics collection for that account immediately.

3.3 Information about other people that appears in your account

Certain features of the Service necessarily involve information about people other than you.

Comments and inbox. If your plan includes the unified inbox, Chiru shows you comments left by other people on the posts you have published through Chiru, so that you can view, reply to, hide, or delete them from one place. To display the inbox, we fetch the commenter's public display name, profile image, and comment text from each platform's API and hold them in a short-lived cache (about five minutes); this commenter content is not stored in our database. What we retain with your account is your own read state for each comment. Automated sentiment labeling of comments is not currently offered, and no comment text is sent to any third-party artificial-intelligence service. We never use commenter information to build profiles of those people, to contact them, or for any purpose unrelated to your account.

Content you publish. Media and captions you publish may depict or refer to other people. You are responsible for having the rights and permissions necessary to publish that content, as described in our Terms of Service.

Team members. See Section 16.

3.4 Media and creative content

Publishing immediately. When you publish a post immediately, your media is streamed straight through our servers to each platform. It is held in memory only for the duration of the upload and is never written to disk or retained. For Instagram, Threads, and Facebook, whose APIs require a fetchable URL, the file is placed in temporary storage for up to fifteen minutes and then deleted.

Scheduling for later. When you schedule a post for a future time, your media must be held somewhere until that time, because your device will not necessarily be online to send it. In that case we store the media, encrypted at rest, in our object-storage provider, and delete it automatically the moment the post publishes, or after 30 days if the post is never published, whichever comes first. A scheduled process runs daily to enforce this.

Editor projects. Editor projects are saved as files on your own device; Chiru's servers do not store them. They remain until you delete them.

Share-card assets. Custom backgrounds, logos, and similar assets you upload for your public share card are stored for as long as the share card uses them.

On-device processing. Where possible, features such as automatic reframing, subject detection, and caption transcription run on your own device rather than on our servers, so that your media does not leave your device for those purposes. The first time you use on-device transcription, the app downloads a speech-recognition model file (approximately 74 MB) from our servers; your audio and video are not uploaded.

Except as described in this Section 3.4, we do not retain your video or image content.

3.5 Information collected automatically

Usage information. When you use the Service, we collect information about the features you use, the screens or pages you visit, the duration of your sessions, and the actions you take, so that we can understand how the Service is used and improve it.

Device and technical information. We collect the type of device and operating system you use, your app version, your browser type, your language and time-zone settings, and technical identifiers generated by the Service itself. In our mobile applications we also receive the device identifiers that Apple and Google provide to support in-app purchases and, if you enable them, push notifications, which are delivered through Expo's push service. Our mobile applications also use Expo's over-the-air update service to deliver app updates.

Network information. Our infrastructure providers, Cloudflare and Railway, process your full IP address to deliver the Service and protect it against abuse. Chiru records the full IP address in its security audit log when you perform sensitive account actions, such as signing in, changing security settings, or making administrative changes, and retains those records as described in Section 10. For free-trial eligibility checks we store only a one-way hash of the address.

Error and performance monitoring. We use Sentry to capture information about errors and crashes, including the app version, device type, and the sequence of actions that preceded an error. We configure Sentry to minimize the personal information included in these reports.

Cookies and similar technologies. Chiru sets no first-party cookies of its own; your session is stored in your browser's local storage. Cloudflare sets a security cookie (__cf_bm) to protect against automated abuse. We use Cloudflare Web Analytics, which is cookieless and does not identify you, to understand aggregate traffic. Our payment provider's checkout runs in an embedded frame that may set its own cookies, governed by that provider's policy. We do not use advertising cookies or third-party tracking cookies. Where required by law, we ask for your consent before setting any technology that is not strictly necessary, and we record the choice you make.

Links to other websites. The Service contains links to third-party websites and platforms. We do not control those sites, and this policy does not apply to them. We encourage you to review the privacy policies of any third-party site you visit.

4. Artificial-intelligence features and your own API keys

Chiru offers optional features that use large-language-model services, such as caption suggestions, hashtag suggestions, and campaign-excerpt generation.

These features operate on a bring-your-own-key basis. They are hidden until you connect your own API key from a supported provider — currently Anthropic, OpenAI, Google (Gemini), and any OpenAI-compatible endpoint you configure. When you use one, only the specific content that feature needs is sent to your chosen provider using your key: a caption suggestion sends the topic you enter; a hashtag suggestion sends the topic you enter; a campaign excerpt sends up to 8,000 characters of the source text you provide. Your key is encrypted with AES-256-GCM before storage and is used only to make requests you initiate. Because the request is made under your own account with the provider, the provider's own terms and privacy policy govern how it handles the content you send.

These bring-your-own-key features are the only way your content is sent to a large-language-model service, and it happens only under your own provider account using the key you supply. Chiru does not send your content to any third-party artificial-intelligence service under its own account. The in-app support assistant answers only by retrieving articles from our own help center and does not send your messages to any third-party AI. Comment sentiment analysis is not currently offered.

We do not use your content, or any output a provider returns, to train artificial-intelligence models of our own, and we do not permit any sub-processor to do so on our behalf.

Some AI-assisted features, such as subject detection for automatic reframing and speech-to-text for captions, run entirely on your own device using models bundled with or downloaded to the application, and do not send your media to any third party.

5. Public profiles and share cards

If you set a public username, the Service can generate a public share card at app.chiru.io/card/your-username. Depending on the options you choose, a share card may display your display name, profile image, bio, selected statistics about your published content, achievements you have earned, and, if you enable it, a list of links you choose to publish.

Share cards are public: anyone with the link can view them. A share card is off by default. You control whether a share card exists at all, which sections are shown, and which statistics and achievements are included, from your profile settings. Disabling your share card removes it from public view.

We do not display your email address, platform access tokens, payment information, or private analytics on a share card.

6. How we use your information, and our legal bases

We use the personal information described in this policy for the following purposes. For people in the European Economic Area, the United Kingdom, and other jurisdictions that require it, we also identify the legal basis on which we rely.

PurposeExamplesLegal basis
Providing the ServiceCreating and maintaining your account; publishing content to connected platforms on your behalf; retrieving and displaying analytics; operating the editors; operating the inbox; processing subscriptionsPerformance of our contract with you
Payments and recordsCharging for subscriptions; keeping transaction records; resolving billing disputesPerformance of our contract; compliance with legal obligations
Security and integrityAuthenticating you; encrypting tokens; detecting abuse, fraud, and automated misuse; protecting our shared access to platform APIs; enforcing rate limitsOur legitimate interest in keeping the Service and its users safe
CommunicationsTransactional emails such as publish confirmations, failure notices, token-expiry warnings, and security alerts; push notifications you have enabled; responding to support requestsPerformance of our contract; our legitimate interest in keeping you informed
Improving the ServiceAnalyzing usage patterns; diagnosing errors; developing new featuresOur legitimate interest in improving the Service; consent, where required
MarketingSending product news and offers, where you have opted inConsent, which you may withdraw at any time
Aggregated featuresComputing anonymized trending-hashtag data (Section 7)Our legitimate interest in providing the feature; the data is not personal information once aggregated
Legal complianceResponding to lawful requests; meeting tax and financial record-keeping obligations; enforcing our TermsCompliance with legal obligations; our legitimate interest in enforcing our agreements

We do not use your personal information for behavioral advertising, and we do not make decisions about you that produce legal or similarly significant effects solely by automated means.

7. Trending hashtags and aggregated data

Chiru may aggregate anonymized hashtag usage across all users to power trending-hashtag suggestions. This aggregate data cannot be traced back to any individual user or post. We do not store post identifiers, user identifiers, or any other information that could link a trending statistic to a specific person.

Regional trending data is based on the country you provide in your profile settings, not on your device location or IP address. If you have not set a country, your activity is included in global trends only. Country information is self-reported and not verified; regional trends reflect whatever country users have chosen to provide. This design is intended to enhance privacy by avoiding location tracking, not to guarantee geographic accuracy.

To protect individual privacy, regional trends are shown only when a sufficient number of distinct users have contributed to that data point. If too few users in a region have used a hashtag, Chiru shows global trends instead.

8. How we share your information

We do not sell, rent, or license your personal information, and we do not share it with advertisers or data brokers. We share personal information only in the following circumstances.

8.1 Connected platforms

When you publish content or request analytics, we transmit your content and API requests to the platforms you have connected, using the credentials you authorized. Each platform's handling of that data is governed by its own terms and privacy policy.

8.2 Sub-processors

The nine connected platforms listed in Section 3.2 also receive your content and API requests when you publish or request analytics; each is governed by its own privacy policy. In addition, we engage the following service providers to operate the Service. Each is bound by a data-processing agreement or equivalent contractual terms and may process personal information only on our instructions.

ProviderPurposeLocation
SupabaseDatabase, authentication, and row-level securityUnited States
RailwayApplication hosting and background processingUnited States
CloudflareContent delivery, edge functions, object storage (R2), bot protection (Turnstile), cookieless web analytics, and network securityUnited States (global edge network)
UpstashHosted Redis cache and rate limitingUnited States
StripePayment processing for United States subscriptions; sales-tax calculationUnited States
PaddleMerchant of record and payment processing for subscriptions outside the United States, including tax calculation and remittanceUnited Kingdom / United States
AppleIn-app purchase processing and subscription management for the iOS applicationUnited States
GoogleIn-app purchase processing and subscription management for the Android applicationUnited States
RevenueCatValidation of mobile in-app purchases and synchronization of subscription stateUnited States
ResendTransactional email deliveryUnited States
ExpoPush-notification delivery and over-the-air app updatesUnited States
SentryError and crash monitoring (API and mobile only)United States
KlipySticker search within the creative editors; receives a per-user identifier with each searchUnited States
PixabayRoyalty-free music search within the creative editorsGermany

We will update this list as our providers change. Material changes to sub-processors that affect the handling of your personal information will be announced in accordance with Section 17.

8.3 Legal requirements and protection of rights

We may disclose personal information where we believe in good faith that disclosure is necessary to comply with a law, regulation, subpoena, court order, or other legal process; to respond to a lawful request from a public authority; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Chiru, our users, or the public. Where legally permitted, we will attempt to notify you before disclosing your information in response to a legal request.

8.4 Business transfers

If Toros Workshop LLC is involved in a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you by email and by a prominent notice in the Service before your information becomes subject to a different privacy policy, and, where the new entity's planned processing differs materially from this policy, we will give you the opportunity to delete your account beforehand.

8.5 With your direction or consent

We may share personal information for any other purpose that you direct or to which you consent at the time of collection.

9. International data transfers

Toros Workshop LLC is located in the United States, and the Service is hosted on infrastructure located in the United States. If you use the Service from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and in any other country in which our sub-processors operate.

Those countries may not provide the same level of data protection as the country in which you live. Where we transfer personal information originating in the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures such as encryption in transit and at rest. You may request a copy of the relevant transfer safeguards by contacting privacy@chiru.io.

10. How long we keep your information

We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer period is required or permitted by law. Where a period below is marked "enforced daily," a scheduled process deletes the data automatically.

CategoryRetention
Account and profile dataLife of account, plus a 30-day grace period after deletion is requested, then permanently erased (enforced daily)
Platform access tokensUntil you disconnect the platform or delete your account; revoked at the platform and deleted from our database at that time
Scheduled-post mediaUntil the post publishes, or 30 days if never published, whichever is sooner (enforced daily)
Temporary publish files (Instagram, Threads, Facebook)Up to 15 minutes
Share-card assetsUntil you remove them or delete your account
Post analyticsSnapshots are retained; the window you can view is 7 days (Free), 30 days (Starter), 1 year (Pro), and 2 years (Agency)
Inbox comment contentNot stored; cached about five minutes. Your read state is retained with your account
Usage and diagnostic dataRetained with your account; we are implementing scheduled anonymization and will update this policy when it is live
Security audit log (including X posting activity, spending-limit changes, and team-member actions)Retained as an immutable record for the life of your account, and thereafter as needed for security and legal purposes
Payment and billing recordsRetained after account deletion in anonymized form for financial record-keeping as required by law
Support conversationsRetained with your account
Consent and agreement recordsLife of account, plus the period required to demonstrate compliance

Analytics data is described by the window over which you can view it, which Chiru controls directly. How frequently analytics are refreshed depends on what each connected platform makes available through its API and is not guaranteed.

11. How we protect your information

We use administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These include:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach of security affecting your personal information, we will notify you and any relevant authorities as required by applicable law, without unreasonable delay, and will provide information about the nature of the breach and the steps we are taking in response.

You are responsible for keeping your password and any API keys you provide confidential, and for notifying us promptly at security@chiru.io if you believe your account has been compromised.

12. Your rights and choices

Subject to applicable law, you have the following rights with respect to your personal information.

Access and portability. You may request a copy of the personal information we hold about you, in-app at Profile → Settings → Download My Data. This generates a ZIP archive containing your data as JSON and CSV files, with a README, delivered to your account email as a link valid for 24 hours. The web app also offers an immediate partial download of your posts and analytics; the emailed archive is the complete export.

Correction. You may update most account and profile information directly in the Service. For anything you cannot change yourself, contact us.

Deletion. You may delete your account in-app at Profile → Settings → Delete Account, or by emailing privacy@chiru.io. When you delete your account, a 30-day grace period begins, during which you can cancel the deletion yourself from within the app. After 30 days, your account data is permanently erased, and all platform access tokens are revoked at each platform and deleted. Content you have already published to third-party platforms is not affected by deleting your Chiru account and must be removed on those platforms directly. Certain records, such as payment records, may be retained for the periods described in Section 10 where the law requires it.

Meta (Instagram, Facebook, and Threads) data deletion. If you connected a Meta account, you may also request deletion of the data Chiru obtained from Meta by removing Chiru from your Facebook or Instagram app settings, or by emailing privacy@chiru.io. Meta-connected data is deleted within 30 days of the request. You can check the status of a Meta-initiated deletion request at chiru.io/data-deletion-status.

Disconnecting platforms. You may disconnect any platform at any time from within Chiru or from the platform's own settings. Disconnecting revokes and deletes the associated access tokens immediately and stops all further publishing and analytics collection for that account.

Objection and restriction. Where we rely on legitimate interests, you may object to that processing, and you may ask us to restrict processing in the circumstances provided by applicable law.

Withdrawing consent. Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing that took place before withdrawal.

Marketing opt-out. See Section 15.

How to exercise your rights. Use the in-app tools described above, or email privacy@chiru.io. We will respond within 30 days, or within any shorter period required by applicable law, and we may extend that period where permitted if a request is complex. To protect your information, we will verify your identity before acting on a request, usually by confirming control of the email address associated with your account. You may authorize an agent to make a request on your behalf, in which case we may require proof of that authorization. We will not discriminate against you for exercising any of these rights.

Complaints. If you are dissatisfied with how we handle your personal information, you have the right to lodge a complaint with the data-protection authority in your country or region. We would appreciate the opportunity to address your concerns first, and you can reach us at privacy@chiru.io.

13. Regional privacy notices

13.1 European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, the UK, or Switzerland, the General Data Protection Regulation, the UK GDPR, or the Swiss Federal Act on Data Protection applies to our processing of your personal information. In addition to the rights described in Section 12, you have the right to receive information about the legal bases on which we rely (Section 6), the right to data portability, and the right not to be subject to solely automated decision-making with legal or similarly significant effects. Our transfers of your information to the United States are described in Section 9. Toros Workshop LLC is the controller of your personal information and can be contacted as described in Section 18. We have not appointed a representative in the EEA or UK under Article 27; if this changes, we will update this policy.

13.2 California

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), gives you the rights described below in addition to those in Section 12.

Categories of personal information we collect. In the preceding twelve months we have collected the following categories of personal information, as those categories are defined in the CCPA: identifiers (such as name, email address, username, and platform account identifiers); commercial information (such as subscription and purchase records); internet or other electronic network activity information (such as usage data and network information); audio, electronic, visual, or similar information (such as the media you schedule or save); professional or employment-related information (to the extent you provide it in a profile or content niche). We do not collect precise geolocation, biometric information, or sensitive personal information as defined by the CCPA, except that your account credentials are treated as sensitive personal information and used only to authenticate you.

Sources and purposes. We collect these categories from you directly, from the platforms you connect, and automatically from your use of the Service, for the purposes described in Section 6.

Disclosure for business purposes. We disclose the categories above to the sub-processors listed in Section 8.2 for the business purposes described there.

No sale or sharing. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under sixteen years of age.

Your CCPA rights. You have the right to know what personal information we collect, use, disclose, and sell; the right to delete; the right to correct inaccurate personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights. Because we do not sell or share personal information, there is no need to opt out. To exercise these rights, use the in-app tools or email privacy@chiru.io. We will confirm receipt within ten business days and respond within 45 days, which we may extend once by a further 45 days where reasonably necessary, with notice to you. We verify requests by confirming control of the email address associated with your account and, where necessary, by requesting additional information that matches what we hold.

Shine the Light. California Civil Code Section 1798.83 permits California residents to request certain information about the disclosure of personal information to third parties for their direct-marketing purposes. We do not make such disclosures.

13.3 Brazil

If you are located in Brazil, the Lei Geral de Proteção de Dados applies. In addition to the rights in Section 12, you have the right to obtain information about the public and private entities with which we have shared your data, and to request the anonymization, blocking, or elimination of unnecessary or excessive data. Toros Workshop LLC is the controller. Our contact for LGPD matters is privacy@chiru.io.

13.4 Other jurisdictions

Residents of other states and countries with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Canada, may have rights similar to those described above. We honor those rights in accordance with the law that applies to you. Contact privacy@chiru.io to exercise them.

14. Children's privacy

The Service is not directed to children under 13. You must be at least 13 years old to create an account, as provided in our Terms of Service, and older where your jurisdiction requires it — for example, some European countries set the minimum age for digital consent at 16. We do not knowingly collect personal information from children under 13. If you believe that a child under 13 has provided us with personal information, please contact privacy@chiru.io, and we will delete the information and terminate the account.

15. Communications, marketing, and push notifications

Transactional communications. We send emails and in-app notices that are necessary to operate the Service, such as publish confirmations, publishing-failure notices, warnings that a platform connection is about to expire and needs reconnecting, billing receipts, security alerts, and responses to your support requests. You cannot opt out of these while you have an account, because they are part of the Service.

Marketing communications. With your consent, we may send you product news, tips, and offers by email. Every marketing email includes an unsubscribe link, and you can also change your preferences in Settings or by emailing privacy@chiru.io. Opting out of marketing does not affect transactional communications.

Push notifications. Our mobile applications can send push notifications, for example when a scheduled post publishes or fails. Push notifications are off until you enable them in your device settings, and you can disable them at any time in the same place.

In-app broadcasts and notifications. We may display notices inside the Service about maintenance, significant changes, or new features. These are not personalized and are not used for advertising.

16. Team and Agency workspaces

Agency plans include team seats, which let you share a Chiru workspace with other people. An account owner (the "Workspace Owner") can invite others (the "Team Members") to work within the owner's workspace, and assigns each Team Member a role that governs which connected platforms they can access and what actions they can take.

When you invite someone, we store the email address you provide and the role you assign, so that we can deliver the invitation and let the recipient accept it even if they do not yet have a Chiru account. A pending invitation is valid for fourteen days; if it is not accepted within that time it expires. When an invitation is accepted, the recipient becomes a member of your workspace, and we store workspace members' email addresses, display names, and roles.

When you are a Workspace Owner, we process your Team Members' personal information (their email addresses, display names, roles, and records of the actions they take in your workspace) on your behalf and on your instructions, and in that respect you are the controller of that information and we are your processor. You are responsible for ensuring that you have an appropriate basis to share Team Members' information with us and to allow them to act on the connected accounts in your workspace.

When you are a Team Member, the Workspace Owner can see the actions you take within the workspace, including the posts you create and publish and the platforms you connect on the workspace's behalf. Your own Chiru account information remains subject to this policy, and we act as controller for it.

The actions Team Members take within a workspace are recorded in our security audit log. Invitation records, workspace membership records, and workspace audit records are retained as described in Section 10.

17. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, the Service, or applicable law. When we do, we will revise the effective date at the top of this policy. If a change materially reduces your rights or materially expands how we use your personal information, we will notify you at least fourteen days before the change takes effect, by email to the address on your account and by a notice within the Service, and where required by law we will seek your consent. Your continued use of the Service after a change takes effect constitutes acceptance of the revised policy, except where consent is required. Prior versions of this policy are available on request.

18. How to contact us

Toros Workshop LLC, doing business as Toros Laboratories, is the entity responsible for the processing of your personal information under this policy.

Privacy inquiries and rights requests: privacy@chiru.io
Security concerns: security@chiru.io
General support: support@chiru.io

Postal address:
Toros Workshop LLC
d/b/a Toros Laboratories
4030 Wake Forest Road, STE 349
Raleigh, NC 27609
United States

Privacy contact: Charles Alvarado, privacy@chiru.io

This policy was last revised on September 1, 2026. It replaces all prior versions.